Adaptive Hybrid Random Forest–Lstm Framework for Network Anomaly Detection in Dynamic Cloud Environments

Authors

  • Tamakloe Vivian Anuoluwa Federal University Dutsin-Ma image/svg+xml
  • Jam Donald Terdoo

DOI:

https://doi.org/10.33003/fjs-2026-1012-5375

Keywords:

Cloud Computing, Network Anomaly Detection, Intrusion Detection System (IDS), Adaptive Mechanism, Machine Learning, Hybrid Random Forest - LSTM

Abstract

The increasing adoption of cloud computing introduces security challenges due to dynamic network traffic. Traditional intrusion detection systems and single-model machine learning (ML) approaches struggle to detect sophisticated cyberattacks and adapt to changing patterns. This study proposes an Adaptive Hybrid Random Forest (RF) - LSTM Framework for Network Anomaly Detection in Dynamic Cloud Environments, designed to leverage the complementary strengths of ML and deep learning (DL) techniques for enhanced anomaly detection performance. Using the CICIDS2017 dataset, preprocessing included data cleaning, feature encoding, normalization, feature selection, and sequence generation. RF handled feature importance ranking and classification, while LSTM captured temporal dependencies. Their outputs were integrated via a weighted fusion mechanism with an adaptive strategy that dynamically adjusts model contributions based on prediction performance.

Experimental results showed RF achieved 99.99% precision; 99.98% across accuracy, recall, F1-score, and ROC-AUC. LSTM achieved 99.84% accuracy, 99.90% precision, 99.73% recall, 99.82% F1-score, and 99.83% ROC-AUC. The hybrid framework further improved performance to 99.96% across accuracy, precision, and ROC-AUC, 99.94% recall, and 99.95% F1-score. ROC analysis showed near-perfect class discrimination, and the adaptive weighting responded well to changing traffic. Statistical validation (Shapiro–Wilk and Wilcoxon signed-rank tests) confirmed that improvements were significant. The results show that the suggested Adaptive Hybrid Framework successfully integrates temporal sequence modeling, adaptive decision fusion, and feature-based learning to produce extremely reliable and accurate anomaly detection in dynamic cloud environments. By increasing detection reliability while preserving flexibility in response to changing cyberthreats, the framework provides a viable way to improve cloud security.

References

Abdulhammed, R., Faezipour, M., Abuzneid, A., & Alessa, A. (2022). Effective feature selection and classification for network intrusion detection using Random Forest. Journal of Cybersecurity and Privacy, 2(3), 512-534.

Alouffi, B., Hasnain, M., Alharbi, A., Alosaimi, W., Alyami, H., & Ayaz, M. (2021). A systematic literature review on cloud computing security: Threats and mitigation strategies. IEEE Access, 9, 57792–57807.

Eguavoen, V. O., Olanrewaju, B. S., & Okafor, C. N. (2025). A hybrid CNN-LSTM and AdaBoost model for classifying intrusion in IoT networks. FUDMA Journal of Sciences, 9(5), 204–212.

Imrana, Y., Xiang, Y., Ali, L., & Abdul-Rahim, Z. (2021). A bidirectional LSTM deep learning approach for intrusion detection in cloud network traffic. IEEE Access, 9, 70846–70861

Khan, M. A., Khan, J., Al-Yasiri, A., & Alomari, A. (2023). Computational complexity and interpretability trade-offs in deep learning for network security: A critical review. Future Generation Computer Systems, 141, 383-400

Kumar, S., Dwivedi, M., Kumar, M., & Gill, S. S. (2024). A comprehensive review of vulnerabilities and AI-enabled defense against DDoS attacks for securing cloud services. Computer Science Review, 51, Article 100604.

Lo, W. W., Layeghy, S., & Portmann, M. (2023). A systematic review of machine learning approaches for network intrusion detection: From static to dynamic models. Computers & Security, 125, 103015.

Mayuranathan, M., Saravanan, S. K., Muthusenthil, B., & Samydurai, A. (2022). An efficient optimal security system for intrusion detection in a cloud computing environment using hybrid deep learning technique. Advances in Engineering Software, 173, Article 103236.

Mishra, S., Jain, T., & Sitaram, D. (2022). A hierarchical approach to conditional random fields for system anomaly detection. arXiv

Modi, N. (2025). AI-powered intrusion detection using CNN-LSTM for cloud and edge networks: A hybrid deep learning approach. Research Square.

Sajid, M., Malik, K. R., Almogren, A., Malik, T. S., Khan, A. H., Tanveer, J., & Rehman, A. U. (2024). Enhancing intrusion detection: A hybrid machine and deep learning approach. Journal of Cloud Computing, 13(1), Article 123.

Tabrizchi, H., & Kuchaki-Rafsanjani, M. (2020). A survey on security challenges in cloud computing: Issues, threats, and solutions. The Journal of Supercomputing, 77(8), 8761-8802

Tufail, A., Namoun, A., Sen, A. A. A., Kim, K. H., Alrehaili, A., & Ali, A. (2021). Moisture computing-based internet of vehicles (IoV) architecture for smart cities. Sensors, 21(11), Article 3783.

Statistical Performance Comparison

Downloads

Published

05-08-2026

How to Cite

Tamakloe, V. A., & Jam, D. T. (2026). Adaptive Hybrid Random Forest–Lstm Framework for Network Anomaly Detection in Dynamic Cloud Environments. FUDMA Journal of Sciences, 10(12), 339-348. https://doi.org/10.33003/fjs-2026-1012-5375